The six questions considered for every approach

Each approach must address six questions, regardless of the model holding the benchmark recommendation. The questions cover rule representation, links to check execution, and options for scoping and recording responses.

1. The six questions, one at a time

Two rules illustrate each approach. Protection of data at rest is a condition either met or not. Minimum password length adds a value to the same rule structure, showing parameter placement in each approach.

Each question compares all three approaches using the same two rules. The questions and encodings are maintained as analysis content; published OSCAL examples provide separate evidence for the illustrated structures.

The legend loads from data/six-questions.json.

The six questions load from data/six-questions.json.

A worked scenario applies all three approaches to one system and counts the artifacts each approach would produce. Separate pages describe strengths and risks: Catalog-first, Component-first and Assessment-first. Open questions lists unresolved issues.